<neynah> I've added http://drawpile.net/ to the voting list. *crosses fingers
neynah has quit [Quit: http://www.kiwiirc.com/ - A hand crafted IRC client]
mnutt_ has joined #sandstorm
englishm has joined #sandstorm
neynah has joined #sandstorm
englishm has quit [Ping timeout: 244 seconds]
englishm has joined #sandstorm
mnutt_ has quit [Quit: mnutt_]
englishm has quit [Ping timeout: 256 seconds]
treyhunner has quit [Quit: No Ping reply in 180 seconds.]
treyhunner has joined #sandstorm
jadewang has quit [Remote host closed the connection]
gopar has joined #sandstorm
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 255 seconds]
patrickod has quit [K-Lined]
patrickod has joined #sandstorm
dlitz has quit [Ping timeout: 240 seconds]
gopar has quit [Remote host closed the connection]
xcombelle has joined #sandstorm
jksonc has left #sandstorm [#sandstorm]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 256 seconds]
mcpherrin has quit [Ping timeout: 244 seconds]
mcpherrin has joined #sandstorm
erikoeurch has joined #sandstorm
mort___ has joined #sandstorm
xcombelle has quit [Quit: Leaving]
xcombelle has joined #sandstorm
xcombelle has quit [Remote host closed the connection]
xcombelle_ has joined #sandstorm
xcombelle_ is now known as xcombelle
xcombelle has quit [Remote host closed the connection]
xcombelle_ has joined #sandstorm
xcombelle has joined #sandstorm
xcombelle_ has quit [Remote host closed the connection]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 265 seconds]
erikoeurch has quit [Ping timeout: 256 seconds]
treyhunner has quit [Quit: No Ping reply in 180 seconds.]
treyhunner has joined #sandstorm
dlitz has joined #sandstorm
mort___ has quit [Quit: Leaving.]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 252 seconds]
neynah has quit [Quit: http://www.kiwiirc.com/ - A hand crafted IRC client]
erikoeurch has joined #sandstorm
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 244 seconds]
erikoeurch has quit [Ping timeout: 250 seconds]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 265 seconds]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 265 seconds]
gopar has joined #sandstorm
xcombelle has quit [Quit: Leaving]
xcombelle has joined #sandstorm
erikoeurch has joined #sandstorm
jadewang has joined #sandstorm
xcombelle has quit [Remote host closed the connection]
xcombelle has joined #sandstorm
jadewang has quit [Ping timeout: 240 seconds]
jadewang has joined #sandstorm
neynah has joined #sandstorm
sasattack_ has quit [Ping timeout: 246 seconds]
jadewang has quit [Remote host closed the connection]
decipherstatic has joined #sandstorm
jadewang has joined #sandstorm
<XgF> kentonv: I see in your new desktop post you were looking for ECC to defend against RowHammer
<XgF> FWIW ECC isn't useful for that
<XgF> (ECC has about a 3/4ths chance of turning the exploit from escallation into DOS and a 1/4th chance of doing nothing of use)
jadewang has quit [Remote host closed the connection]
<dwrensha> XgF: is there anything one can do to protect against RowHammer, then?
<XgF> Use Rowhammer resistant RAM
<XgF> This mostly means DDR4
xcombelle has quit [Remote host closed the connection]
<XgF> The other option (which is rather hard) is for the OS to work out your RAM & DRAM controller's banking layout and leave gaps between processes
<dwrensha> XgF: re ECC, slowing down the attack by a factor of 4 still sounds better than nothing
<XgF> dwrensha: it converts the attack from privilege escallation into kernel panic
<XgF> 3/4ths (ish) of the time
<dwrensha> even better
<dwrensha> I'll definitely notice a kernel panic
<XgF> But, like, if you're buying expensive RAM, just buy expensive RAM which has fixed the issue :P
jadewang has joined #sandstorm
neynah has quit [Quit: http://www.kiwiirc.com/ - A hand crafted IRC client]
mnutt_ has joined #sandstorm
neynah has joined #sandstorm
jadewang has quit [Ping timeout: 265 seconds]
<mnutt_> is it expected that ekam will always trigger a rebuild when files are changed? is anyone using it while developing through the vagrant nfs bridge?
<kentonv> XgF: Thanks but Mark Seaborn, the Google Chrome security engineer who actually made a working exploit out of rowhammer, disagrees. In their tests they were unable to trigger rowhammer in ECC RAM.
<kentonv> XgF: that said, yes, I plan to buy DDR4. ECC is "defense in depth".
sasattack-deskto has joined #sandstorm
<kentonv> mnutt_: In continuous mode it should trigger rebuilds any time something in the source tree changes (but it doesn't watch installed files, etc.). It's entirely possible that it doesn't work well on non-local filesystems since sometimes they don't support inotify correctly.
<mnutt_> kentonv: thanks, good to know. I’m guessing it’s something to do with the nfs bridge.
<kentonv> mnutt_: I think what you want is somehow for the guest machine to be the host of the filesystem, and for the host machine to access said filesystem over network to the guest.
<kentonv> mnutt_: Because the guest machine is the one running ekam so needs to know about all changes.
<mnutt_> yeah, I think you’re right. for the time being I’ll probably just touch the files from the guest when I need a rebuild
erikoeurch has quit [Ping timeout: 246 seconds]
<XgF> kentonv: the person who demonstrated the Chrome exploit did so on ECC systems
<XgF> kentonv: ECC repairs aren't done regularly enough to compensate for rowhammer
<kentonv> XgF: do you have a reference for that?
<XgF> This was a discussion I had with them on another channel
<kentonv> I'll ask Mark next time I see him but the last time I talked to him he said ECC got the job done in practice (even if not theoretically foolproof).
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 240 seconds]
mnutt_ has quit [Quit: mnutt_]
mnutt_ has joined #sandstorm
mnutt_ has quit [Quit: mnutt_]
dwrensha has quit [Ping timeout: 246 seconds]
mnutt_ has joined #sandstorm
dwrensha has joined #sandstorm
mnutt_ has quit [Quit: mnutt_]
jadewang has joined #sandstorm
jadewang has quit [Ping timeout: 245 seconds]